“Scams have become industrialized”: Bitdefender’s Bogdan Botezatu on the most common scams in 2026

During an exclusive interview with Cybernews, Bogdan Botezatu, Bitdefender’s Senior Director of Threat Research and Reporting, explained how scams exploit trust across devices, AI’s role, how to protect yourself, and what to do if you’ve already been scammed.
Scams in 2026 rarely announce themselves with broken English or an obviously fake link. They can begin with a polished social media ad, continue through WhatsApp or a phone call, and end on the laptop used for online banking. Each step looks ordinary on its own, making the full attack much harder to recognize.
“The biggest change is the industrialization of scams. AI has not invented fundamentally new types of fraud, but it has made existing scams cheaper, faster, and far more convincing,” says Bogdan Botezatu.
Scams on an industrial scale
Investment offers, fake delivery notices, and bogus technical support are still the most common scams in 2026. The biggest change, Botezatu argues, is how cheaply criminals can run these schemes and how many people they can reach.
“Generative AI allows criminal groups to generate localized ads, websites, messages, and synthetic voices at scale, as well as break into markets that were not easily accessible before because of language constraints,” he says.
AI also helps criminals test and adapt their campaigns much faster. An operation can now hold real-time conversations with people in several countries without hiring a large team that speaks each language.
Scammers now even compete with each other for victims, which gives them further reason to make each approach more convincing. Information from data breaches helps them personalize requests and impersonate brands a person already uses.
“So far, AI has raised the average quality and reach of scams rather than created an entirely new form of fraud,” Botezatu explains. “That may sound less dramatic than an autonomous AI criminal, but it is arguably more dangerous: proven scams can now be deployed globally, cheaply, and at an industrial scale.”
How do online scams manufacture trust?
A request from a suspicious email address may be easy to dismiss. The same request will appear much more credible if it looks like it came from your bank, a business you use, or someone you know. Botezatu says scammers are putting much more effort into building trust as consumers become more familiar with traditional scam tactics.
“A suspicious link or an unsolicited investment offer may no longer be enough, so criminals invest more effort in building credibility through familiar platforms, brands, business accounts, and even compromised accounts belonging to people the victim knows,” he says.
An important change in 2026 is that scammers now build credibility in multiple stages. It can begin through a simple ad, then a business account, followed by a call or a website. None of these proves that the inquiry is legitimate, but together they can build trust.
“Each step makes the previous one appear more credible,” he explains, “Once that trust is established, the specific scam almost becomes secondary.”
Afterward, criminals can adapt, move the conversation across platforms, and try different requests without needing to reestablish trust. “If one payment request fails, they may pivot to a fake emergency, an investment opportunity, account verification, or technical support,” Botezatu says. “Their goal is not simply to sell one convincing lie, but to build a relationship they can eventually monetize.”
These tactics can reach large audiences, but scammers can also single out and target individuals personally. A targeted scam can be much harder to question, since it may use a hacked account or stolen personal details and exploit a close relationship to make the request feel genuine.
“AI now helps them reproduce writing styles, translate conversations, and generate convincing voices or video, but the underlying tactic is unchanged: create familiarity, add urgency, and prevent the victim from independently checking the story,” Botezatu says.
Who can fall for a scam?
There is no single profile of someone who gets scammed, Botezatu says. He argues that timing and circumstances can matter more than a person's technical knowledge.
“Effectiveness depends less on intelligence or technical literacy than on whether the criminals reach the right person, with the right story, at the wrong moment,” Botezatu says.
Every day, mundane situations can create the exact circumstances needed for a successful scam. “We are all in a hurry, and that’s the moment we make mistakes: that parcel we were expecting and missed the delivery, the motorsports tickets that are on sale for the next 30 seconds, or the reminder that our millionth subscription is due,” he explains. “These are all daily lures that attackers use most of the time.”
Botezatu credits Bitdefender’s Global Scam Intelligence Report 2026 with putting numbers to this problem, often described through anecdotal stories. Measuring exposure, interactions, and campaigns across channels helps to understand the scale beyond individual experiences.
Why protection needs to work across devices
In 2026, a scam can jump from app to app and device to device, starting with a simple ad on your phone and ending on the computer. Botezatu describes how criminals keep the same scam moving.
“A campaign may begin with an ad on a phone, move into WhatsApp or a voice call, and end on a laptop or desktop where the victim is asked to log into online banking, authorize a transfer, or install remote-access software,” he says.
Scams that move between devices are not new. Back in 2023, the FBI warned about “Phantom Hacker” schemes combining phone calls, remote access to computers, and criminals even posing as bank staff. Botezatu’s concern in 2026 is that AI scams are cheaper, faster, and more convincing.
By the time someone is asked to transfer money or grant access to their computer, a malicious actor has already established trust through prior encounters. That is why expecting people to connect every warning sign under pressure has limits. According to Botezatu, modern protection tools need to recognize the whole scam chain cross-platform.
“Effective protection does not only layer technologies and early warning systems, but can also correlate security events across devices and reconstruct the broader scam journey,” he says. “Instead of evaluating a suspicious link, call, or message in isolation, a modern security solution can recognize separate stages of the same attack across multiple devices owned by the victim.”
The key point is that the scam may begin on one device, while the actual theft happens later on another. “We can no longer rely on device security, given that individuals use multiple devices across the day,” Botezatu adds.
How to spot a scam in 2026
Bad grammar can still give a scam away, but good grammar doesn't make a message safe. Botezatu says what matters more is what the sender wants you to do.
“A modern scam can have perfect grammar, localized language, professional branding, and a valid HTTPS connection,” he says. “AI has removed many of the spelling mistakes and awkward phrasing that once gave scams away.”
An unexpected password-reset message or a request for banking details to recover a parcel deserves a closer look. Be just as cautious with requests for verification codes or access to your computer, especially if the sender rushes you or discourages you from checking the request independently.
“People should focus less on how polished a message looks and more on what it asks them to do,” Botezatu says. “In the end, if something looks too good to be true, it probably is a scam.”
If you’re unsure about a message, Bitdefender Scamio can give you a second opinion. The free AI chatbot checks messages, screenshots, links, and QR codes for signs of fraud and suggests next steps. Use it for a second opinion, not a guarantee of safety.
What to do after being scammed
If you've already sent money or shared any personal details, the priority is to stop further damage as soon as possible. End contact with the scammer and deal directly with the affected services. “If money, credentials, or device access have already been shared, speed matters,” Botezatu says.
The response mostly depends on what the scammer received:
- Money or banking details. Contact your bank immediately using an official contact method. Ask whether it can stop, trace, and reverse the payment. Have your bank block affected cards or accounts.
- Access to your device. Disconnect the device from the internet if the scammer may still have access. Remove remote-access software installed at their request and run a full security scan.
- Passwords or account access. From a trusted device, change compromised passwords, including anywhere you reused them. Sign out active sessions and enable multifactor authentication.
- Evidence and reporting. Keep messages, phone numbers, transaction details, and screenshots. Report the incident to the relevant platform and authorities.
Finally, Botezatu urges victims not to let embarrassment delay their response: “Shame only buys the scammer more time.”
Can you scam a scammer?
For those of you tempted to take it upon yourselves to teach a scammer a lesson, we asked Botezatu whether there is ever a good reason to engage with a scammer. For ordinary users, his answer is almost always no.
“Simply replying to a message changes the amount of information the crooks are able to infer from your number,” Botezatu warns. Keeping the conversation going gives the scammer more opportunities to collect personal details or pressure you.
“‘Scamming the scammer’ can also create false confidence,” he says. “The person on the other end does this professionally and may already know more about you than you realize.”
There are plenty of videos where people successfully mess with scammers. But Botezatu points to the precautions professionals take: controlled accounts, isolated systems, and defined procedures. That does not make the same behavior safe for an ordinary user.
“For everyone else, the safest conversation with a scammer is the one that ends immediately,” Botezatu says.